THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-77704 (LOW 2.7) — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including

[NVD] CVE-2026-77704 (LOW 2.7) — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including

mednvdPublished 2026-08-29

CVE-2026-77704 CVSS: 2.7 LOW Published: 2026-08-29T06:17:44.150

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting ap

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-77704